Consumer Health Data Privacy Policy

Last updated: August 17, 2026

This policy is provided separately from the general privacy policy for people in Washington State, under the My Health My Data Act, and for people in Nevada under SB 370. It describes consumer health data specifically. Everything here is also true of the general policy; nothing in one contradicts the other.

Much of what Elderhub holds is consumer health data, and much of it is about someone other than the person who typed it. The app also holds care coordination and financial information that may be connected to that health data. That is the point of the app, and it is why this page exists.

Categories of Consumer Health Data Collected

Elderhub does not collect precise location data. The app never requests location permission and contains no location code. It does not collect biometric identifiers, does not read from Apple Health, and does not connect to any monitor, wearable or medical device. Every value in the app was typed in by a person.

Sources of Consumer Health Data

One source only: what you and the other members of your care circle type into the app. Elderhub does not buy, license, receive or infer health data from any other party, and does not obtain it from data brokers, health care providers, pharmacies, insurers or advertising networks.

Purposes for Collecting and Using It

Consumer health data is never used for advertising, for profiling, for training any model, for any form of behavioral analytics, or for any purpose beyond running the features you turned on.

Categories of Data Shared, and With Whom

Elderhub does not sell consumer health data, and has never done so. Selling it, in the sense the My Health My Data Act uses, would require your separate written authorization; there is no circumstance in which it is offered for sale, so no such authorization is ever sought.

Elderhub shares health data as part of operating the service in two ways:

Two other services are used for limited functions. Apple provides Sign in with Apple, in-app purchases, and push notification delivery. A missed check-in push contains the recipient's name and a factual no-check-in message, not medication or diagnosis details. RevenueCat receives the purchase receipt and linked app account identifier for subscription checks, not the care record. No advertising network, data broker, analytics vendor, or affiliate receives the care record, because there are none.

Storage and Retention

A record can remain local to one phone without an account or care circle. When you explicitly share it, the app keeps a local offline copy and syncs a shared copy to Supabase. The local store uses iOS file protection with NSFileProtectionCompleteUntilFirstUserAuthentication; it is not end-to-end encrypted. Deleted synced rows may remain as server tombstones while the care circle exists, and an audit log can retain old and new snapshots for medications, doses, people, and membership changes.

Your Rights

You may, at any time and at no cost:

To exercise any of these by email, write to jackwallner+medlist@gmail.com. A request is verified by confirming control of the email address or Apple relay address on the account. There is no fee, and exercising a right will never result in a worse experience in the app.

If a request is refused, the reason will be given in the reply, and you may appeal by replying to it. If an appeal is denied you may complain to the Washington State Attorney General.

Data About Other People

Most of what is in Elderhub is health data about someone other than the person who entered it. When you add a person who will not be using the app themselves, Elderhub asks you to confirm that they know you keep this record or that you are the person who makes their health decisions, and records that confirmation. Please enter someone else's health information only if that is true. A person who later joins with their own account is shown exactly who is in the group and what each member can see about them, before anything of theirs syncs, and may leave at any time.

Changes

Material changes to this policy will be posted here with a revised date before they take effect, and consumer health data already collected will not be used for a new purpose without consent.

Contact

Jack Wallner
jackwallner+medlist@gmail.com

Privacy Policy · Support · Terms of Use